ExamGecko
Question list
Search
Search

Related questions











Question 29 - PCNSC discussion

Report
Export

A customer has a five-year-old firewall in production in the time since the firewall was installed, the IT team deleted unused security policies on a regular basis but they did not remove the address objects and groups that were part of these security policies.

What is the best way to delete all of the unused address objects on the firewall?

A.
Import the configuration in Expedition, remove unused address objects, and reimport the configuration.
Answers
A.
Import the configuration in Expedition, remove unused address objects, and reimport the configuration.
B.
Using CLI execute request configuration address-objects remove-unused-objects.
Answers
B.
Using CLI execute request configuration address-objects remove-unused-objects.
C.
Go to Address Objects under the Objects tab and click on Remove unused objects.
Answers
C.
Go to Address Objects under the Objects tab and click on Remove unused objects.
D.
Search each address object with Global Find and delete if it shows that the address object is not referenced.
Answers
D.
Search each address object with Global Find and delete if it shows that the address object is not referenced.
Suggested answer: B

Explanation:

To delete all of the unused address objects on the firewall, the best method is:

B . Using CLI execute request configuration address-objects remove-unused-objects

This CLI command is designed to identify and remove all unused address objects in the firewall's configuration. It is the most efficient and accurate method for cleaning up unused objects without manually checking each one.

Palo Alto Networks - PAN-OS CLI Quick Start: https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-cli-quick-start

Palo Alto Networks - Removing Unused Address Objects: https://knowledgebase.paloaltonetworks.com

asked 23/09/2024
Ivan Ramirez
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first